Shadow AI is AI software or an AI feature used for work without the organization knowing, reviewing, or approving it. The risk is not merely that an employee found a new chatbot. The tool may receive client files, meeting audio, source code, personal information, or access to connected systems under consumer terms.
You can find most material use without surveillance theatre. Combine a short amnesty survey with records the business already maintains, then talk to the people doing the work. The objective is a truthful inventory and safer alternatives, not a list of culprits.
§1Declare an amnesty window
Tell the team why you are looking, what counts as AI, and what will happen with answers. For the initial inventory, say that good-faith disclosure will not be punished. Reserve action for deliberate concealment, serious misconduct, or failure to stop a dangerous use after instruction.
A threat-first audit produces clean spreadsheets and dirty reality. People hide useful tools, managers rename them, and the riskiest use remains invisible.
Sample languageFor the next ten business days, disclose any AI tool or AI-enabled feature used for work. Good-faith disclosure during this inventory will be used to make approval decisions, not as the basis for discipline.
§2Run a five-minute survey
Ask for the product, account email or type, work task, frequency, information entered, outputs used, integrations, whether a client is involved, and what would break if the tool disappeared. Ask about built-in features, transcription, coding, design, and browser extensions.
Let people report uncertainty. “I think this feature uses AI” is useful. Do not ask employees to interpret privacy terms; that is the reviewer’s job.
- Which tool or feature do you use?
- What task does it help with?
- What information goes in and what comes out?
- Is it connected to company files, email, code, or customer systems?
- Is the account free, personal, or company-managed?
- Would work stop, slow down, or continue without it?
§3Review expense reports
Search company cards, reimbursements, and accounts-payable descriptions for AI vendors and common product names. Look at recurring small software charges and vague categories such as productivity, transcription, writing, design, and developer tools.
An expense proves purchase, not use or data exposure. Add it to the interview list. Conversely, free products will never appear in finance records, so this step cannot stand alone.
§4Check browser extensions carefully
If the business already manages browsers, review the installed-extension inventory for AI assistants, summarizers, transcription tools, writing aids, and extensions with broad page access. Examine permissions, publisher, install source, users, and update history.
Do not ask employees to surrender personal browsing histories. Focus on company-managed devices and existing administrative data. An extension that can read and change every webpage deserves review even if its AI function seems minor.
§5Review SSO and identity logs
Use your identity provider’s application list and sign-in records to find apps accessed with company identities. Look for OAuth grants and connected applications, not just formal single sign-on integrations.
Prioritize tools with many users, sensitive permissions, external sharing, or connections to mail, storage, calendars, source code, CRM, and ticketing. Absence from SSO does not mean absence from use; personal accounts remain possible.
§6Ask managers about the workflow
Take the combined list to team leads and ask where the tool enters the process, what output is relied on, and what client promises apply. Managers often know the workflow but not the product name; employees know the product but not the contract.
Observe a real example using synthetic or non-sensitive data. This frequently reveals connected sources, automatic retention, sharing, or final decisions that a survey missed.
§7Triage the list
Classify each use by data sensitivity and consequence. Also note integration reach, vendor terms, number of users, client commitments, and reversibility. Review the high-high quadrant first.
Pause uses involving credentials, highly sensitive information, unapproved automated decisions, or broad system access until assessed. Low-risk tools can continue temporarily with public or synthetic data under a review deadline.
- Data: public, internal, confidential, personal, highly sensitive.
- Consequence: convenience, client deliverable, operational decision, decision about a person.
- Access: pasted input, file upload, repository connection, broad account permissions.
- Control: personal account, company account, enterprise agreement, administrative settings.
§8Decide: approve, constrain, replace, or stop
Approval should name the allowed task, account, data, reviewer, owner, and next review. A constrained approval might permit public-data brainstorming but prohibit client files. Replacement offers a safer approved tool for the same need. Stopping should be reserved for uses whose risk cannot be reduced adequately.
Explain the decision. If the approved route is slower, expensive, or unclear, shadow use will return. Governance has to compete with the convenience that created the problem.
§9Close data and access exposure
For tools you stop, revoke OAuth grants, remove extensions, cancel subscriptions, export necessary records, request deletion, and document the outcome. Change credentials if they were exposed. Assess whether a privacy, security, client, or legal notification is required.
Do not assume deleting the account deletes prompts, uploads, derived data, or backups immediately. Check the applicable terms and obtain confirmation where the risk warrants it.
§10Publish the approved path
Give employees one source of truth: approved tools, allowed uses, prohibited data, and a simple request form. Explain how fast normal review takes and who answers questions.
Pair the register with a short AI policy. Include contractors and new starters. A policy without a visible tool list leaves everyone guessing about product-level decisions.
§11Repeat without turning it into surveillance
Repeat the survey and record review quarterly at first, then adjust based on change. Add AI prompts to procurement, onboarding, offboarding, and vendor reviews so discovery becomes ordinary operations.
Track useful measures: unknown tools found, time to decide, overdue reviews, revoked risky integrations, and employee questions. A falling question count is not necessarily success; it may mean the reporting culture has gone quiet.
§12What to tell clients
Say that you maintain an inventory through employee disclosure and existing administrative records, review tools by data and consequence, and document approvals. Do not claim perfect detection.
Use the RFP answer guide for precise language and the vendor checklist for consistent reviews. The honest position is not “shadow AI is impossible here.” It is “we have a repeatable way to find, assess, and correct it.”
§13Make the second audit easier
After the first review, add small prompts to existing processes. Procurement asks whether a product contains AI and what data it receives. Onboarding explains the approved register. Offboarding removes AI accounts and connected grants. Project kickoff asks whether a client restricts AI. Security review includes extensions and OAuth permissions.
Give experiments an expiry date. A 14-day trial using public or synthetic information can be recorded with an owner and automatically close unless somebody requests production approval. This keeps the register focused without driving experimentation underground.
Watch for recurrence rather than promising perfect prevention. If the same kind of unapproved tool returns, investigate the underlying need: the approved product may be missing a feature, review may take too long, or the rule may be poorly explained. Fixing the workflow is usually more durable than blocking another domain.
Share the results without naming individuals unnecessarily. Tell the team how many tools were approved, constrained, replaced, or stopped; what changed; and where to request a tool. Closing the loop proves that disclosure led to decisions, not a silent blacklist.
§14Use evidence proportionately
Do not buy an expensive discovery product before checking whether your existing browser, identity, finance, and endpoint tools already expose useful records. Start with the systems you operate lawfully and understand. More telemetry does not automatically create a better decision.
Document where each signal came from, the period covered, and its blind spots. Expense data misses free tools. Identity logs miss personal accounts. Browser inventories miss mobile apps. Surveys depend on memory and trust. Overlap gives confidence; no single source proves absence.
Where monitoring may affect employee privacy, consult applicable law, workplace policy, and counsel. Tell people what administrative data is reviewed and why. The purpose is to protect company and client information, not to infer productivity from prompts or browsing behavior.
Keep only the evidence needed for decisions, incidents, and accountability. Avoid building a permanent archive of employee AI activity merely because logs are available. Good governance includes restraint in its own collection of data.
§15Frequently asked questions
What is shadow AI?
It is an AI tool or AI-enabled feature used for work without the organization’s knowledge, review, or approval.
Can network monitoring find every AI tool?
No. It can miss personal devices, embedded features, renamed services, and offline use. Combine administrative records with an amnesty survey and workflow interviews.
Should employees be disciplined for reporting unapproved AI?
A no-blame initial inventory usually produces better information. Handle deliberate concealment, repeated violations, or serious misconduct through normal processes.
How often should we audit for shadow AI?
Quarterly is a practical starting point in a fast-changing environment. Adjust to your risk, tool turnover, and client obligations.
If you need the policy as well as the questions, the complete Clause Zero kit is $79.